Known vulnerabilities in macOS - page 9

Vendor: Apple Inc.
Software: macOS
Software CPE: cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Total vulnerabilities: 3367
Public exploits: 126
Known exploited (KEV): 83
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting macOS macOS is affected by 3367 known vulnerabilities: 39 critical, 535 high, 533 medium, 2260 low Critical High Medium Low

Vulnerabilities (3367)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU124410 - Improper input validation
CVE-2026-20651
CWE-20 Low
No
No
15.7.5 24G624, 14.8.4 23J319, 26.3 25D125 25.03.2026 SB2026032506
SB2026021190
SB2026021188
#VU124409 - Information Exposure Through Log Files
CVE-2026-20668
CWE-532 Low
No
No
15.7.5 24G624, 14.8.5 23J423, 26.3 25D125 25.03.2026 SB2026032506
SB2026032507
SB2026032509
and 3 more
#VU124391 - Improper Access Control
CVE-2026-28882
CWE-284 Low
No
No
26.4 25E246 25.03.2026 SB2026032504
SB2026032514
SB2026032539
and 3 more
#VU124390 - Improper Access Control
CVE-2026-28867
CWE-284 Low
No
No
26.4 25E246, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032509
and 4 more
#VU124383 - Improper input validation
CVE-2026-28852
CWE-20 Low
No
No
26.4 25E246, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032509
and 4 more
#VU124372 - Improper Access Control
CVE-2026-20631
CWE-284 Low
No
No
26.4 25E246 25.03.2026 SB2026032504
#VU124371 - Improper Access Control
CVE-2026-28826
CWE-284 Low
No
No
26.4 25E246 25.03.2026 SB2026032504
#VU124367 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-20632
CWE-22 Low
No
No
26.4 25E246 25.03.2026 SB2026032504
#VU124363 - Use After Free
CVE-2026-20687
CWE-416 Low
No
No
26.4 25E246, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032509
and 3 more
#VU124357 - Memory corruption
CVE-2026-28832
CWE-119 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124356 - Improper input validation
CVE-2026-28892
CWE-20 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124355 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-28876
CWE-22 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 3 more
#VU124353 - State Issues
CVE-2026-28888
CWE-371 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124352 - Improper input validation
CVE-2026-28886
CWE-20 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 5 more
#VU124351 - Improper Access Control
CVE-2026-28838
CWE-284 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124350 - Improper input validation
CVE-2026-28821
CWE-20 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124342 - Improper input validation
CVE-2026-28878
CWE-20 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.7 24G720 25.03.2026 SB2026032504
SB2026032507
SB2026032509
and 5 more
#VU124336 - Improper Authorization
CVE-2026-28877
CWE-285 Low
No
No
26.4 25E246, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032514
and 3 more
#VU122667 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-20660
CWE-22 Low
No
No
26.3 25D125, 14.8.4 23J319, 15.7.5 24G624 11.02.2026 SB2026021188
SB2026021190
SB2026021191
and 4 more
#VU121026 - Insufficiently Protected Credentials
CVE-2025-14524
CWE-522 Low
No
No
14.8.5 23J423, 15.7.5 24G624, 26.4 25E246 07.01.2026 SB2026010741
SB2026010781
SB2026010782
and 23 more


Showing elements 161 - 180 out of 3367